It's not about hacking; it's about threat modeling using a widespread and well-understood implementation that behaves similarly in many ways to a real threat. Basically, if your APT identification tech can't detect Google Chrome updates being pushed out over your network, you won't be able to detect real malicious actors. A true threat would act in a very similar way, except the payload would be more malicious than Chrome updates.
It's an interesting thought experiment; but no, there are no concrete conclusions.